raul.ip

2.4K posts

raul.ip

raul.ip

@ethicraul

Head of Security @piplabsxyz, building @StoryProtocol | ex @OpenZeppelin | Co-founder @ethichub. Builder, Music Lover. 🇪🇸 in 🇦🇷 Opinions are my own.

Buenos Aires เข้าร่วม Ocak 2015
1.6K กำลังติดตาม1.2K ผู้ติดตาม
ทวีตที่ปักหมุด
raul.ip
raul.ip@ethicraul·
We are starting a series of articles on the security measures taken in preparation for @StoryProtocol mainnet, and after. I think it's a good read for young projects as well, since the first article also reads as "As a web3 project, how do I procure security audits, configure audit contests, bug bounties, etc?". It goes over dev process, and our ecosystem efforts to help key projects get their code reviewed as well. Shout out to the great teams that have audited our mainnet launch and beyond @fuzzland @slowmist @HalbornSecurity @trust__90 @FuzzingLabs Contest and bug bounty providers: @cantinaxyz Our ecosystem auditing partners: @BlockSecTeam @NethermindSec and @HalbornSecurity
Story@StoryProtocol

Security is a core part of Story’s DNA. It's a constant, deliberate practice that protects everything from our network to the community members and ecosystems that depend on it. A closer look ↴

English
53
10
154
12.8K
raul.ip รีทวีตแล้ว
jacob
jacob@jacobmtucker·
Building something called Scroll 📜, a way for people to share text snippets (mini-blogs, excerpts, etc) with embedded paid content. Allow your readers to purchase your favorite agentic prompt, latest gossip, or premium content within seconds... directly on your piece!
jacob tweet media
English
2
7
50
746
raul.ip
raul.ip@ethicraul·
Thanks for the kind words @PatrickAlphaC , great having you in our council. "I think this is a very valuable role, and it’s something that the Story Protocol does very well. Their security council is often pinged for advice; we discuss industry hacks and open dialogue on how changes in the security landscape should drive action on the Story team. In this scenario, I think it’s important to separate this from a “Security Council” that has defined on-chain roles they often act on, vs. “Security Advisors” who advise on actions." Go read the full article!
Patrick Collins@PatrickAlphaC

x.com/i/article/2042…

English
0
2
8
325
raul.ip รีทวีตแล้ว
jacob
jacob@jacobmtucker·
Introducing Confidential Data Rails (CDR), a new primitive for securely transferring private data. Here's how it works ↓
jacob tweet media
English
30
23
95
5.8K
raul.ip รีทวีตแล้ว
Joestar
Joestar@Joestar_sann·
so let me get this straight all of ai twitter was telling people to buy a mac mini to run openclaw, which is literally just a framework, an orchestration layer that sends api requests to actual ai models. something you can run on a $5/month vps. which is exactly what i do btw but when google drops gemma 4, an actual large language model that you can run and fine-tune locally on that same mac mini, with no api costs, no subscriptions, no third party dependencies, completely yours under apache 2.0 the ai community is silent you were buying $800 hardware to run a wrapper but ignoring the actual ai model that would justify that hardware this tells you everything you need to know about the average iq of ai twitter
English
724
1.3K
22.2K
814.7K
raul.ip
raul.ip@ethicraul·
Yeah we are totally going to put guardrails on this tech you guys
raul.ip tweet media
English
0
0
0
48
Fede’s intern 🥊
Fede’s intern 🥊@fede_intern·
In a security panel in EthCC people are saying that regulation is what is needed to solve security and secops in crypto. I worked with multiple big corporations in regulated industries. Their security is really really bad. Believing that regulation solves these things is funny and sad.
English
21
10
119
8K
raul.ip รีทวีตแล้ว
Story Engineers
Story Engineers@StoryEngs·
Story v1.6.1 Aeneid Testnet Required Upgrade This release introduces Distributed Key Generation (DKG) and Confidential Data Rails (CDR) on Aeneid Testnet. This lays the foundation for on-chain confidential data management. story.foundation/blog/confident… Upgrade triggers at block height 16332000 (Apr 1, 2026). Only Aeneid nodes need upgrade. Read More ↴
English
12
15
75
8.2K
raul.ip รีทวีตแล้ว
TrustSec
TrustSec@TrustSecAudits·
‼️ MAJOR ANNOUNCEMENT TLDR: - Trust Security is now TrustSec. New name, new logo, new website. - We’re setting industry standards on how security teams communicate their work. Our entire portfolio is now on open display - every audit, bounty, contest win. Full transparency, zero gatekeeping. - Going further, we present every competitor audit ran in parallel to us, on same commit. No cherry picking. It’s a pure measure of skill, and the results are conclusive. - Same team, same standard, same depth. The quality never changed. Now the visibility catches up. Everything's in place to hit entirely new ceilings. Full breakdown below ⤵️
English
10
15
105
15K
raul.ip รีทวีตแล้ว
Story
Story@StoryProtocol·
Congrats to @verse_eight on their $5M seed round! In gaming, value typically flows to a handful of studios. Verse8 flips that model with an AI platform where anyone can turn ideas into games. 3.5M users, 5K active creators, and 25K games since launch. Built on Story ↴
Verse 8 | Why Code, Just Verse 8@Verse_Eight

Verse8 raised $5M in a seed round backed by Story Foundation, NEXPACE, Neowiz, MARBLEX, and NEXUS. A stacked lineup of industry leaders strategically backing AI-native game creation. The creation meta just changed. 🧵

English
98
45
207
19.4K
raul.ip รีทวีตแล้ว
Hari
Hari@hrkrshnn·
These types of attacks are hard to economically catch today. An AI-forward solution would precisely catch malicious packages, but it's too expensive today to deploy at scale, i.e., scan every single public package all the time. So the next best thing is signature-based or fixed static rules, like what @SocketSecurity, @snyksec, @wiz_io, and others are doing. The downside is they miss novel attacks like this, and you're always playing catch-up. Platforms like @npmjs, @pypi, and @github should take more responsibility here and proactively fix and invest in preventing these attacks.
Andrej Karpathy@karpathy

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

English
9
4
21
9.6K
raul.ip
raul.ip@ethicraul·
@CondeSala20 Veo que la gente empieza a entender la verdadera ventaja de crypto.
Español
1
0
4
1.8K
Antonio Ayuso.
Antonio Ayuso.@CondeSala20·
Un familiar intentó sacar 30.000 euros de su banco habitual y la respuesta que obtuvo fue una auténtica vergüenza. Ha sido un cliente fijo de este importante banco durante 24 años. Llamó para retirar el dinero y le dijeron que no, que tenía que ir en persona a la sucursal. Fue a la sucursal bancaria y pidió retirar los 30.000 euros, y acto seguido le preguntaron: "¿por qué lo quieres sacar?". Esta persona no quiso dar detalles y simplemente contestó: "Es para un asunto personal que prefiero no contar en público, y además es mi dinero, no creo que tenga que dar muchas explicaciones mas". A lo que el empleado del banco le contestó: "Lo lamento pero, a menos que nos digas exactamente para qué quieres el dinero, no puedes retirarlo". Esto es una práctica cada vez mas habitual en la mayoría de bancos, y es algo que debería impactarte y aterrorizarte, porque es nuestro dinero y parece que ya ni siquiera nos pertenece.
Español
942
3K
9.6K
621.6K
P.M
P.M@p_misirov·
BRING SECURITY COMPETITIONS BACK LET THE AI’S FIGHT
P.M tweet media
English
2
1
27
2.2K
raul.ip รีทวีตแล้ว
The Lunduke Journal
The Lunduke Journal@LundukeJournal·
SystemD has added birth date storage in order to comply with Brazil and California Age Verification laws. Let that sink in. A Linux init system now handles Age Verification. github.com/systemd/system…
The Lunduke Journal tweet media
English
262
406
2.3K
371.1K
raul.ip
raul.ip@ethicraul·
@XMihura Ya vivimos en esa realidad
Español
0
0
0
92
Mihura
Mihura@XMihura·
no voy a comentar sobre lo de hodio porque... bueno xd pero jugueteando con el Gemini y tal con contextos largos... yo creo que la gente no es consciente de la capacidad que existe ya con los modelos actuales para destilar información, eh literalmente el mundo de 1984 es una chorrada en comparación con lo que es posible hoy en día no me refiero a la tecnología del futuro, me refiero a la tecnología que existe hoy al alcance de cualquiera una AI driven panopticon es algo técnicamente posible a día de hoy, la única barrera es el coste (tanto de cómputo como de deployment) y las inercias económico-sociales, pero no hay una barrera técnica no quiero ni imaginar en un futuro con super-inteligencias mucho más poderosas y con un coste mucho más bajo yo creo que este es uno de los riesgos que le atormenta al Dario, pero he de admitir que es un riesgo real yo soy un optimista, y creo que la humanidad no va a poner en funcionamiento algo así porque para qué pero el hecho de que ya es posible, chills
Español
8
5
59
9K
raul.ip รีทวีตแล้ว
Juan Ramón Rallo
Juan Ramón Rallo@juanrallo·
El gobierno montando una Stasi digital para vigilar, documentar y archivar quién dice qué cosas que le desagradan a ese gobierno. ¿Qué creéis que harán los políticos con esa información salvo utilizarla para castigar (por diversos medios) a sus "enemigos"?
Español
110
1.1K
4K
93K
raul.ip รีทวีตแล้ว
Gabriel Araújo
Gabriel Araújo@GabrielAraujoES·
🔴 La Junta Electoral Central JEC avala que se pueda votar identificándose simplemente mostrando la app miDNI, pero sin ninguna verificación criptográfica. La nueva medida solicitada por el gobierno de Sánchez, permitirá identificarse en una mesa electoral, mostrando simplemente en el móvil un DNI digital sin verificación por QR en tiempo real. Teniendo en cuenta que es mucho mas fácil falsificar cualquier app que un DNI físico, ¿qué puede salir mal? Hasta WhatsApp verifica por QR la identidad de los usuarios. Pero para votar en España no hará falta ni siquiera eso. eldebate.com/espana/2026031…
Gabriel Araújo tweet media
Español
352
2.2K
2.8K
229.7K
Pol Lanski 🥩,🤖
Pol Lanski 🥩,🤖@Pol_Lanski·
I support delegate incentives because governance quality compounds when delegates are regular, have deep and extensive context and are accountable and visible. Those who disagree: what's the strongest argument against this direction?
English
6
0
12
348
raul.ip รีทวีตแล้ว
Dark Web Informer
Dark Web Informer@DarkWebInformer·
‼️🇪🇸 A threat actor is allegedly selling a Spanish IBAN leads database containing 8,145,987 lines. The sample data includes full names, addresses, emails, phone numbers, IBAN numbers, and associated bank names from major Spanish financial institutions.
Dark Web Informer tweet media
English
6
41
100
16.2K